<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: support]]></title>
    <link>http://securityratty.com/tag/support</link>
    <description></description>
    <pubDate>Tue, 23 Sep 2008 00:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</link>
      <guid>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place. </p>

<p>Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf. </p>

<p>If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections. </p>

<p>Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> published this year in International Security that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers: </p>

<p>Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved. </p>

<p>Abrahms has an alternative model to explain all this: People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States. </p>

<p>The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida. </p>

<p>For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist. </p>

<p>All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion. </p>

<p>This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups. </p>

<p>We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.</p>

<p>This essay <a href="http://www.wired.com/print/politics/security/commentary/securitymatters/2008/10/securitymatters_1002">previously appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=QW5fM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=QW5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YCnjM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YCnjM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 01:48:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_seven_habit.html">The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</link>
      <guid>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>
Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place.
</p>

<p>
Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf.
</p>

<p>
If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections.
</p>

<p>
Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> (.pdf) published this year in <cite>International Security</cite> that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers:
</p>

<p>
Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved.
</p>


<p>
Abrahms has an alternative model to explain all this:  People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States.
</p>

<p>
The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida.
</p>

<p>
For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist.
</p><p>
All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion.
</p><p>
This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups.
</p><p>
We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=16939d16056d6d01accd415177a76dbb" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=16939d16056d6d01accd415177a76dbb" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=igbdM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=igbdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=CO91m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=CO91m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rBiKm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rBiKm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=qO8rM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=qO8rM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=0b0DM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0b0DM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nYn4m"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nYn4m" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=EcnRm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=EcnRm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UhYOM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UhYOM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/408903389" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/408903390" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/408903390/securitymatters_1002">Security Matters: The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kit Comes with Disclaimer]]></title>
      <link>http://securityratty.com/article/f53d9a8c84706cb980c1a5fe00e3e2f8</link>
      <guid>http://securityratty.com/article/f53d9a8c84706cb980c1a5fe00e3e2f8</guid>
      <description><![CDATA[Such disclaimers make you wonder what's the point of including a notice forwarding the responsibility for the upcoming cybercrime activities to the buyer, when the seller himself is offering daily...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOPmoVr-3KI/AAAAAAAACNQ/L7Fxlk4j_Gg/s1600-h/1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOPmoVr-3KI/AAAAAAAACNQ/IZ-phgyZJpY/s200-R/1.JPG" /></a>Such disclaimers make you wonder what's the point of including a notice forwarding the responsibility for the upcoming cybercrime activities to the buyer, when the seller himself is offering daily updates with undetected bots, and is promising to include new exploits within the kit.<br />
<br />
For the time being, this recently released copycat web exploitation malware kit, includes two PDF exploits, IE snapshot, and naturally MDAC, with a DIY builder for the binary. Here's the disclaimer, greatly reminding us of <a href="http://www.theregister.co.uk/2008/04/28/malware_copyright_notice/">Zeus's copyright notice</a> : <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQEl4WjyJI/AAAAAAAACNw/bup8hAFSOIA/s1600-h/3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQEl4WjyJI/AAAAAAAACNw/J0Uxe3C2IPI/s200-R/3.JPG" /></a>"<i>Purchasing this product, you hold the full responsibility for its usage and for consequences which may have been caused by incorrect usage or the usage with some evil intent or violation of the usage rules. The author excludes the placement of the scripts somewhere on the Internet, you can only place them on localhost, virtual machine or on a test botnet (minibotnet). WARNING! The usage of this product with evil intent leads to the criminal responsibility!</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQE_GioZeI/AAAAAAAACN4/-TgImabe7zw/s1600-h/5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOQE_GioZeI/AAAAAAAACN4/TC5-5hqbJ0I/s200-R/5.JPG" /></a>What happens when the buyer tries to resell the kit? - "<i>If you try to resell, decode, remove the boundaries, you will lose all the  support, updates and guarantees.</i>" which is surreal considering that the kit is open source one, and just like we've seen with a recent modification of Zeus if it were to include unique features -- which it doesn't -- others would build upon its foundations.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SOQFHcVCuhI/AAAAAAAACOA/gyW259ojaII/s1600-h/7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SOQFHcVCuhI/AAAAAAAACOA/XvJB5TF7UCE/s200-R/7.JPG" /></a><br />
Going through the exploitation statistics of a sample campaign, you can clearly see that out of the 859 unique visits 250 got exploited with outdated and already patched vulnerabilities. Therefore, diversifying the exploits set would have increased the number of exploited hosts.<br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQFq13TnPI/AAAAAAAACOI/Ubkw74c4Wn0/s1600-h/9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQFq13TnPI/AAAAAAAACOI/nvO4FBQ3s3k/s200-R/9.JPG" /></a>With IE6 visitors exploited at 46% as a whole, it would be hard not to notice that just like Stormy Wormy's historical persistence of using outdated vulnerabilities, a great majority of today's botnets have been aggregated using old exploits.<br />
<br />
Trying to enforce the intellectual property of a malware kit means you're claiming ownership, and therefore the disclaimer becomes irrelevant.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7NZmM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7NZmM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DOidM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DOidM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7V8tm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7V8tm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wAlLm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wAlLm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6EqeM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6EqeM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZZ3BM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZZ3BM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0wv6m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0wv6m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409055131" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 22:58:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/usage rules">usage rules</category>
      <category domain="http://securityratty.com/tag/usage">usage</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/pdf exploits">pdf exploits</category>
      <category domain="http://securityratty.com/tag/incorrect usage">incorrect usage</category>
      <category domain="http://securityratty.com/tag/evil intent">evil intent</category>
      <category domain="http://securityratty.com/tag/evil intent leads">evil intent leads</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409055131/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Saved by SaaS: Data backup via software as a service]]></title>
      <link>http://securityratty.com/article/1ccc2dbc192adf243aa44f3ec3c9dd5f</link>
      <guid>http://securityratty.com/article/1ccc2dbc192adf243aa44f3ec3c9dd5f</guid>
      <description><![CDATA[SaaS data backup is becoming an increasingly attractive option for many companies that have difficulty with in-house backup. SaaS providers handle support and maintenance of a variety of applications...]]></description>
      <content:encoded><![CDATA[SaaS data backup is becoming an increasingly attractive option for many companies that have difficulty with in-house backup. SaaS providers handle support and maintenance of a variety of applications over the Internet without requiring their clients to invest in any servers or install software on-site.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1abdf4f18ff6dda9a90283fb7b3e8c53:m1I%2Boss1okw%2BW%2BDgsf1bSNzlQjEhC9b1cDhiTRKU4jbJWwWcmqDYHuQC6W5L3U%2BDLVtmm4r19Ftf'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:63195fa65154eb7c9f82b4058bdb73f1:lWC7pR0V0TX6w0hzjfJxjizzo%2BKZ8Z3p4Gr6EWFYVOSOkmJIlhB5An7spSPmFVx%2FTC6b9DG6u%2F1%2F8A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ae1333c9b75150ba58ce64a4f6e62c53:74TIj0K5qYbqbfio1rcNuhZ13PBZIxvp2niPJwY%2Bie2IOoBv0R0Ft6WVGOYCPAsH7oizcxQ%2Bj13BqA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2ddbf6978d160c23c34af27f34f092db:3XcCP3DCsCqnz51pWpjHSAWzhB0VFxTSATZ4SbONSKZMvu%2F6xKB8XiyKLvRe6DS8487MZzDjJE9x4A%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9656ce5584e9fb21da19c3d93a247f12" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9656ce5584e9fb21da19c3d93a247f12" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/install software on-site">install software on-site</category>
      <category domain="http://securityratty.com/tag/saas data backup">saas data backup</category>
      <category domain="http://securityratty.com/tag/increasingly attractive option">increasingly attractive option</category>
      <category domain="http://securityratty.com/tag/in-house backup">in-house backup</category>
      <category domain="http://securityratty.com/tag/variety">variety</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/difficulty">difficulty</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9656ce5584e9fb21da19c3d93a247f12">Saved by SaaS: Data backup via software as a service</source>
    </item>
    <item>
      <title><![CDATA[John Zanni Delivers Keynote at the Tier1 Hosting Transformation Summit]]></title>
      <link>http://securityratty.com/article/e6b5db3dba618f48e7fa728ff2173006</link>
      <guid>http://securityratty.com/article/e6b5db3dba618f48e7fa728ff2173006</guid>
      <description><![CDATA[As General Manager of Worldwide Hosting, John Zanni is a key guy for every Managed Service Provider delivering Microsoft based solutions. At this years Hosting Transformation Summit , John gave a...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="spla_image" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/spla-image.png" width="244" align="left" border="0"> As General Manager of Worldwide Hosting, <a href="http://www.microsoft.com/presspass/features/2008/jul08/07-29qazanni.mspx" target="_blank">John Zanni is a key guy for every Managed Service Provider</a> delivering Microsoft based solutions. At this year&#8217;s <a href="http://www.hostingtransformation.com/na/2008/" target="_blank">Hosting Transformation Summit</a>, John <a href="http://www.hostingtransformation.com/na/2008/agenda.php" target="_blank">gave a keynote</a> titled: &#8220;Leadership Perspective: Cloud Computing – is Virtualization Enough?&#8221;</p>
<p>John talked <a href="http://blogs.zdnet.com/BTL/?p=10007" target="_blank">about Microsoft’s mission</a>, his perspectives on key industry trends and market opportunity; he touched on <a href="http://www.betanews.com/article/Will_Microsofts_virtualization_spur_a_lot_more_cloud_computing/1221867502" target="_blank">Cloud Computing and Virtualization</a> and took some Q&amp;A from the audience of <a href="http://technet.microsoft.com/en-us/serviceproviders/default.aspx" target="_blank">Managed Service Provider</a> executives.</p>
<p>One of his first proclamations - Microsoft has really embraced the heterogeneous environment. Really? How in the world is Microsoft going to help convince IT line managers, or mid level managers to believe this statement? I think they have a long way to go to achieve this vision with any credibility in the marketplace.&nbsp; I do know that they are making small strides.</p>
<p>Microsoft has been widely credited with some very good blogs that are self critical and introspective. They have also been quite active in the standards boards within <a href="http://www.dmtf.org/home" target="_blank">DMTF</a> and many others such as <a href="http://www.openwsman.org/" target="_blank">Open WSMAN</a> and CIMON (<a href="http://www.openpegasus.org/" target="_blank">Open Pegasus</a>). Microsoft in February published 30,000 pages detailed technical specifications – protocol documentation for Exchange, since that time they have published another 15,000 pages. They have had over 224,000 downloads since February 21, 2008. Thus they are trying to be more open by making some of these <a href="http://www.microsoft.com/about/legal/intellectualproperty/protocols/default.mspx" target="_blank">secret sauce protocol resources</a> <a href="http://msdn.microsoft.com/openprotocols" target="_blank">directly available on the web</a>.</p>
<p>So for now, I will take a very cautious wait and see approach to this proclamation. Time will tell.</p>
<p><strong>Trends</strong></p>
<ul>
<li>Rapid growth continues
<li>Hosting Competition has a new face
<ul>
<li>Platform gorillas (amazooglesoft)
<li>Ad supported Web 2.0 hosters (Google, Facebook,) </li>
</ul>
<li>Utility Cloud Computing models are expanding to non-traditional hosting companies
<ul>
<li>Wells Fargo vSafe - hard to believe that a big bank would start to offer a SaaS offering
<li>New tools and markets digital ribbon, CohesiveIT </li>
</ul>
</li>
</ul>
<p><a href="http://mshostingsummit08.spaces.live.com/blog/cns!4308FE7290C0AF4!245.entry" target="_blank">IDC Data shows that growth of SaaS ISV’s is the biggest layer of growth</a>. The fastest growing services are complex, custom applications. IDC says this area will be bigger than the hosting area in the next 5 years. John said that <a href="http://blogs.msdn.com/ukisv/archive/2008/09/22/the-route-to-saas-and-beyond-final-seminar-places-remain-2nd-oct-08.aspx" target="_blank">Microsoft is spending a lot of time, money and energy on this right now</a>.</p>
<p>John said:</p>
<blockquote><p>“when Microsoft thinks about the building blocks that make-up the cloud, <a href="http://www.microsoft.com/virtualization/" target="_blank">virtualization is a core piece</a> of the puzzle. However you also need also identity services, Operating system with standard set of libraries to tap into… or remote storage that application developers will tap into.. Developers will consume these set of services, but you will also need a set of tools to manage your physical, virtual and geographically distributed datacenter infrastructure.” (that is where ScienceLogic comes in!!)</p>
</blockquote>
<p>He went on to say,</p>
<blockquote><p>“In some ways, virtualization enables decentralization – allows you to move from data centers, enables fast scaling out, business to move from on premise to the cloud and off again…. Automation is very important – this will help you scale your business – this is core to your future success.”</p>
</blockquote>
<p>He talked about a new breed of knowledge worker: He called them Digital Natives (compared to grey haired guys like me who are left out of this category).</p>
<p>Definition of a Digital natives? A young adult who has grown up with cellphone, web based applications, Facebook account, as their primary mode of communications.</p>
<p>John commented that we are 5 years into a 10 year journey. Only 12% of all servers in the world are virtualized today… in the next 4 years it will double to 25%. This is <a href="http://www.interopnews.com/news/vmware-ceo-maritz-addresses-virtualization-the-cloud-and-cha.html" target="_blank">the time to think through</a> how this business will affect you.</p>
<blockquote><p>‘Virtualization without good management is more dangerous than not using virtualization in the first place.” Thomas Bittman, Analyst Gartner</p>
</blockquote>
<p>Patching and provisioning nightmare – no scalable administration – sprawl chaos.</p>
<p>John posed a question to the audience: How do you partner to provide the ISV support in application development with specific market needs… partner by keeping the <a href="http://tarrysingh.blogspot.com/2008/09/microsofts-coo-on-cloud-computing.html" target="_blank">hosting to SaaS solution</a> providers up and running and provide the quality of service that their customers expect…. Complimentary services of storage and backup is a big win with a huge market-upside over the next 5 years..</p>
<p>John said that <a href="http://blogs.msdn.com/mhpta/archive/2008/04/10/microsoft-hosting-summit-2008.aspx" target="_blank">Microsoft continues</a> to make&nbsp; <a href="http://www.virtualization.info/2008/07/microsoft-bets-on-hosting-providers-to.html" target="_blank">huge investments with Managed Service Providers</a>.</p>
<ul>
<li>Investing in the <a href="http://www.microsoft.com/hosting/" target="_blank">windows hosting platform</a>
<li>Hyper V and SQL2008 GoLive program - getting beta code out to service provides to find as many bugs as early as possible.
<li><a href="http://blogs.msdn.com/stevecla01/archive/2008/09/22/explaining-software-plus-services.aspx" target="_blank">Software + Services (S+S)</a> incubation center program
<li>Partnering for <a href="http://tarrysingh.blogspot.com/2008/09/microsofts-coo-on-cloud-computing.html" target="_blank">cloud platform market offers</a>
<li>Cloud platform guidance and best practices </li>
</ul>
<p>During the Q&amp;A, David Burns from Cincinnati Bell asked the very best question… “when are you going to make it easier for the Service Provider market to <a href="http://www.virtualization.info/2008/09/microsoft-to-allow-3rd-parties-to.html" target="_blank">deal with the Microsoft Service Provider Licensing Agreement (SPLA)</a> quarterly statistics pull and change the SPLA pricing to be more efficient and creative for the new Virtualization and Cloud offerings you have talked about?&#8221;</p>
<p>John’s response: “We hear your frustrations loud and clear and are working on some new ideas for the future version of SPLA.” My interpretation – &#8220;Dear Service Providers don’t expect anything new or easier to deal with in the next 6 months!&#8221;</p>
<p>His closing remarks: &#8220;Cloud is evolving = very early stages, lots of hype, but think of how this evolution will effect your business and how you can plug into it.”</p>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:00:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service provider market">service provider market</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider executives">service provider executives</category>
      <category domain="http://securityratty.com/tag/john">john</category>
      <category domain="http://securityratty.com/tag/john zanni">john zanni</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft based solutions">microsoft based solutions</category>
      <source url="http://blog.sciencelogic.com/john-zanni-delivers-keynote-at-the-tier1-hosting-transformation-summit/09/2008">John Zanni Delivers Keynote at the Tier1 Hosting Transformation Summit</source>
    </item>
    <item>
      <title><![CDATA[Network World Coverage of ScienceLogic at Interop]]></title>
      <link>http://securityratty.com/article/27b0a46be99117829b3a5801b8947a5d</link>
      <guid>http://securityratty.com/article/27b0a46be99117829b3a5801b8947a5d</guid>
      <description><![CDATA[We were all really excited to have the opportunity to illuminate Sevick and Wetzel about ScienceLogics value proposition at Interop
Yesterday, they posted a terrific blog post about what they saw at...]]></description>
      <content:encoded><![CDATA[<p>We were all really excited to have the opportunity to illuminate Sevick and Wetzel about ScienceLogic’s value proposition at Interop.
<p>Yesterday, they <a href="http://www.networkworld.com/community/node/33059" target="_blank">posted a terrific blog post</a> about what they saw at Interop. Fortunately, ScienceLogic was one of the technologies that they highlighted from the show. I have written earlier posts about <a href="http://blog.sciencelogic.com/whats-up-with-the-washington-posts-biz-section-coverage-of-local-business/05/2008" target="_blank">how difficult it has been</a> to gain smart, insightful coverage for our solutions with technology media.
<p>I have to say that they really got it! And it feels so good. We know that we have a bit of a hidden gem of a product here at ScienceLogic and will be working overtime in the coming months to take our business and products to a “Blue Ocean” environment that will shock and surprise many others in the media. However Sevick and Wetzel will be amongst the first to get a close-up on why and how we will deliver a new paradigm to this marketplace in 2009!
<p>A few excerpts from their post:<br />
<blockquote>
<p>“We noticed yet more specialty network management vendors, leading us to wonder how the market can support such a plethora of them, and we felt empathy for IT teams that have to master yet more interfaces.”
<p>“Application performance management and application acceleration vendors were well represented. Such products play well in today’s climate because they allow enterprises to get the most out of existing IT investments instead of buying more “stuff”. One particularly interesting vendor we talked to was <a href="http://www.sciencelogic.com/">ScienceLogic</a>. They are integrating IT infrastructure and application monitoring into a single, not-very-expensive platform that will serve mainstream business well. This is smart, and we predict they will give the CA’s, BMC’s, HP’s and IBM’s of the world a run for their money.”</p>
</blockquote>
<p>&nbsp;
<p>Check out the <a href="http://www.networkworld.com/community/node/33059" target="_blank">blog post here</a> and keep <a href="http://www.networkworld.com/community/appview" target="_blank">App Performance View</a> on your radar..<a href="http://www.networkworld.com/community/node/33059"></a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 11:36:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrific blog post">terrific blog post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/application acceleration vendors">application acceleration vendors</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/application performance management">application performance management</category>
      <source url="http://blog.sciencelogic.com/network-world-coverage-of-sciencelogic-at-interop/09/2008">Network World Coverage of ScienceLogic at Interop</source>
    </item>
    <item>
      <title><![CDATA[TIBCO BusinessEvents 3.0]]></title>
      <link>http://securityratty.com/article/de1f0c5b81d2a653775eaade21547299</link>
      <guid>http://securityratty.com/article/de1f0c5b81d2a653775eaade21547299</guid>
      <description><![CDATA[I was pleased to read the Paul Vincents post, TIBCO BusinessEvents 3.0 . TIBCO has always had a forward thinking vision for distributed computing and this release of BE 3.0 is another step in the...]]></description>
      <content:encoded><![CDATA[<p>I was pleased to read the Paul Vincent&#8217;s post, <a title="Permalink" href="http://tibcoblogs.com/cep/2008/09/22/tibco-businessevents-30/">TIBCO BusinessEvents 3.0</a>.    TIBCO has always had a forward thinking vision for distributed computing and this release of BE 3.0 is another step in the right direction.  TIBCO now has the only commercial-off-the-shelf (COTS) event processing platform on the market that supports distributed event processing, multi-agent architectures, distributed object caching, extensibility, continuous queries, state management and state-of-the-art rules.</p>
<p>Even thought TIBCO&#8217;s BusinessEvents does not yet support Bayesian Classifiers, Artificial Neural Networks and other advanced decision support algorithms, it is just a matter of time before TIBCO will add these advanced features &#8220;out of the box&#8221;.  On the other hand, the extensible nature of TIBCO&#8217;s BE makes it possible to add probabalistic computing functionality, however this requires quite a lot of programming and integration work.</p>
<p>When I see a great release like this for TIBCO, it makes me a little nostalgic for &#8220;the good old days&#8221; travelling the world in the front of the aircraft for TIBCO.   TIBCO has a rich and diverse customer base.  This customer base includes financial services companies; however, TIBCO is much less dependent on financial services than other event processing companies.   So, with TIBCO you not only get great technology, but rock-solid stability in an unstable and uncertain business world.</p>
<p>As a side note, an S&amp;P analyst recently <a href="http://www.thecepblog.com/2008/09/18/sp-downgrades-tibco-to-sell-on-financial-services-exposure/" target="_blank">downgraded</a> TIBCO&#8217;s stock <a href="http://online.barrons.com/quotes/main.html?symbol=tibx">(TIBX)</a>, primarily due to chao in the financial services sector.    Because of TIBCO&#8217;s global reach and stability, plus forward vision, advanced technologies and many years of commericial success, the S&amp;P downgrade will create a buying opportunity for TIBCO stock.</p>
]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 01:54:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tibco businessevents">tibco businessevents</category>
      <category domain="http://securityratty.com/tag/tibco">tibco</category>
      <category domain="http://securityratty.com/tag/tibco stock">tibco stock</category>
      <category domain="http://securityratty.com/tag/tibcos">tibcos</category>
      <category domain="http://securityratty.com/tag/tibcos businessevents">tibcos businessevents</category>
      <category domain="http://securityratty.com/tag/tibcos global reach">tibcos global reach</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/financial services sector">financial services sector</category>
      <category domain="http://securityratty.com/tag/vision">vision</category>
      <source url="http://www.thecepblog.com/2008/09/24/tibco-businessevents-30/">TIBCO BusinessEvents 3.0</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Microsoft to drop support for Office 2003 SP2]]></title>
      <link>http://securityratty.com/article/b198798d7e7869c7c885fd51f4f32e8b</link>
      <guid>http://securityratty.com/article/b198798d7e7869c7c885fd51f4f32e8b</guid>
      <description><![CDATA[Microsoft Corp. warned users that it will drop support for Office 2003 Service Pack 2 (SP2) in three weeks. The company's policy is to support an Office service pack for 12 months after it releases a...]]></description>
      <content:encoded><![CDATA[Microsoft Corp. warned users that it will drop support for Office 2003 Service Pack 2 (SP2) in three weeks. The company's policy is to support an Office service pack for 12 months after it releases a successor.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:b4e6ea1c626e0894fcf7a5092234fd7c:HAVMVA%2Fjm4yWdZlST6HczagtF259BHXMAVjnyWAUXPSoC4IO2jEapVFYNkaTwS2oKNXtdxXuXo%2BFTipu5rk4bNTBFm3J%2BVNVasws0tobuz0%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:35ae8004b7d97c3254b00661e1d9f770:6VnQSnAz5ENmsu0RdEmtJXg8%2BBQ2Co8oGGyygJkSmhIOh90Jk7q5X6N3CwQXpdQa37PeIJY%2F8KrNswqWGj75RLnT3O6fevnZWl5aMEY75Ro%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9b485ac9d40b2fb60f2f869cd1dd31be:%2F5nLfUxb4cMuQalWxI9dm51KNShd%2F7ftfNFXd21Ivv9l7dLtByYu0LfTLbCUTADftvn%2BfeIcfUUV17NQYTS7wtI4nm9eM9y3XJAaPW4QWo0%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:845d1b08c8f547bcb731c826bd4e4d88:NBUeYO49A9BE8P%2BasnbmzZo2cdlrwp9syYTLn758uNCyyFe6P156I79%2BaMg9Iq26H1rXgY4OnQPcQdnRbEvMWR6M1re9q5llrBnT6scjthQ%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=cc4ac6a2c511f6539517da07a2bdcd83"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=cc4ac6a2c511f6539517da07a2bdcd83" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=cc4ac6a2c511f6539517da07a2bdcd83" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/office">office</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/office service pack">office service pack</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/drop support">drop support</category>
      <category domain="http://securityratty.com/tag/microsoft corp">microsoft corp</category>
      <category domain="http://securityratty.com/tag/sp2">sp2</category>
      <category domain="http://securityratty.com/tag/successor">successor</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=cc4ac6a2c511f6539517da07a2bdcd83">Microsoft to drop support for Office 2003 SP2</source>
    </item>
  </channel>
</rss>
